VulnScope — 以套件為主體的 CVE 查詢工具- CRITICAL9.1CVE-2026-48039Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
- MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vul…
- MEDIUM5.0An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c.
- MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM4.0ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images.
- MEDIUM6.5A heap buffer overflow flaw was found in 389 Directory Server.
- MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalida…
- MEDIUM6.9Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow.
- LOW2.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.
- MEDIUM5.9Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- MEDIUM6.5vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
- MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution.
- MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution.
- MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
- CRITICAL9.8Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.
- MEDIUM4.8Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authent…
- MEDIUM5.9Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.
- LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provid…